load balancing with two ASAs running independent

Unanswered Question
Feb 27th, 2008
User Badges:

I have two ASA 5540 firewall running independently behind my internet router.

The reason I can't run active-active mode on the ASAs because I want to enable remote access vpn on both ASAs.

Internet Router address :

ASA1 outside address: (NAT pool = - 99; PAT =

ASA2 outside address: (NAT pool = - 199;PAT =

ASA1 inside address:

ASA2 inside address:

Both inside interfaces of the ASAs connected to a 6509 box same vlan. Vlan int ip address is

All of them running EIGRP. CEF is enabled on the internet router and 6509.

I also have a few static NAT on ASA1 pointing to inside servers

Will this design work?

Will my internet traffic (inbound and outbound) be load balanced?

Will there be asymmetric routing problem? (by default CEF does per destination)

  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)


This Discussion